wordpress: multiple vulnerabilities
| Package(s): | wordpress | CVE #(s): | CVE-2016-7168 CVE-2016-7169 | ||||||||||||||||
| Created: | September 9, 2016 | Updated: | September 30, 2016 | ||||||||||||||||
| Description: | From the arch Linux advisory: CVE-2016-7168 (cross-site scripting) A cross-site scripting vulnerability via an image filename, reported by SumOfPwm researcher Cengiz Han Sahin. CVE-2016-7169 (directory traversal) A directory traversal vulnerability in the upgrade package uploader, reported by Dominik Schilling from the Wordpress security team. | ||||||||||||||||||
| Alerts: |
| ||||||||||||||||||
